🔍 SIGINT Monitor

Geopolitical Signal Intelligence • Real-time Monitoring & Analysis

Status Live • Collecting
Sources 4 APIs • Rotating
Data Collected 500+ files/day
Analysis Daily 06:00 UTC

📊 Collection Metrics Last 24h

500+
Files Collected
1.2K
Articles Indexed
115
Coordinated Narratives
12
Signal Queries

🚨 Red Line Triggers

🔴 RED 1: Sleeper Cell Narrative
FBI announces "Iranian sleeper cell" arrest without supporting evidence
🔴 RED 2: Classification Escalation
Congressional briefing suddenly classified (previously unclassified)
🔴 RED 3: Coordinated Media
3+ outlets identical threat alert within 2 hours (detected via multi-source)
🔴 RED 4: Prosecutor Reassignment
Federal prosecutors moved from corruption cases
🔴 RED 5: Voting Emergency
Voting law emergency provisions framed as Iran/national security

📈 Top Signal Queries

Rubio Iran policy
99 articles • State Dept positioning
Congressional briefing Iran
93 articles • Oversight activity
Sleeper cell Iran threat
87 articles • RED 1 watch
Netanyahu war planning
90 articles • Regional escalation
DHS budget emergency
81 articles • Authority expansion watch

📋 Latest Analysis Report Generated 06:00 UTC

Loading latest report...

TIER 1 Information Control & Classification

✓ Classified NIC Assessment Leaked
Contradicts public messaging
✓ Congressional Oversight Blocked
Hegseth & Rubio testimony delayed

TIER 2 Law Enforcement Expansion

⏳ FBI/DHS Budget Supplemental
$50B floated — monitoring framing

TIER 3 Media Narrative Shift

✓ "Domination" → "Prolonged Campaign"
Narrative prep for extended ops

TIER 4 Personnel Changes

✓ Hardline Faction Consolidation
Hegseth + Rubio + Witkoff active

🔬 Methodology: Complete Framework

Collection Phase: Four independent data sources (GDELT, NewsData, NewsAPI, Reddit) rotate through 156 signal queries continuously. 500+ files accumulate daily.

Analysis Phase: Daily at 06:00, 14:00, 22:00 UTC, all collected data is analyzed for:
• Multi-source coordination (same story across 2+ APIs simultaneously)
• Red line triggers (false flag prep, emergency powers, classified escalation)
• Operational patterns (10 institutional capture indicators)
• Threat assessment (AUTO-RATE: GREEN/YELLOW/ORANGE/RED)

Deduplication: v2 Algorithm deduplicates by actual news outlet (not aggregator copies). Only flags as "coordinated" when multiple independent APIs report the same story simultaneously.

Institutional Monitoring: 12 threat actor categories (144 queries) detect:
• Evidence destruction & cover-ups
• Emergency authority consolidation
• Justice system manipulation (prosecutors, judges)
• Election infrastructure compromise
• False flag operation indicators
• Intelligence community purges
• Military command structure changes
• Surveillance authority expansion
• Media control & narrative lockdown
• Financial system weaponization
• International alliance breaking
• Institutional legitimacy erosion

⚙️ Operational Pattern Detectors (10)

🔴 CRITICAL Patterns (4):
Simultaneous Action: Multiple agencies act on same day/hour
Narrative Lock: 3+ major outlets report identical messaging within hours
Oversight Evasion: Inspector general removed, subpoenas ignored, FOIA delayed
Legal Framework Rewrite: Emergency laws, precedent violated, constitutionality ignored

🟠 HIGH Patterns (6):
Opposition Suppression: Political enemies face coordinated legal/media pressure
Authority Consolidation: Emergency authority replaces normal process
Personnel Loyalty Purge: Career officials replaced with loyalty-tested appointees
Information Control: Media blackouts, whistleblower retaliation, document destruction
Financial Coercion: Opponent accounts frozen, transaction monitoring weaponized
International Isolation: Treaty withdrawals, ally abandonment, UN rejection

📊 Threat Assessment Levels

🟢 GREEN (0 signals): Normal institutional function → Passive monitoring

🟡 YELLOW (1-2 signals): Isolated institutional anomalies → Active monitoring, pattern watching

🟠 ORANGE (3-5 signals): Coordinated pressure on institutions → High alert, daily briefings

🔴 RED (6+ signals OR 3+ CRITICAL patterns): INSTITUTIONAL CAPTURE / ORGANIZED POWER CONSOLIDATION → EMERGENCY PROTOCOLS, IMMEDIATE ESCALATION

📡 Data Sources (4 APIs)

GDELT
Real-time indexing • 500k+ sources • 1 query/5 sec
NewsData
News aggregation • 80k+ outlets • 600/day
NewsAPI
US/Western focus • 500/day free • Timestamp sorting
Reddit
Community signals • Read-only API • 4 subreddits

💰 Cost Analysis

Collection (24/7 passive): FREE (all APIs are free tier)

Analysis (3x daily):
• Single analysis: ~18,000 tokens = $0.08
• 3x daily (06:00, 14:00, 22:00 UTC): ~54,000 tokens/day = $0.24/day
• Monthly: ~$7 (standard) or ~$2.50 (bulk tier)

Total Cost: ~$7/month for comprehensive institutional monitoring
Status: ✅ Negligible • ✅ Cost-effective • ✅ Fully operational

🎯 Query Breakdown

Core Queries (12): Original Iran war + domestic authority signals

Threat Actor Categories (144 expanded): 12 categories × 12 keywords each
• Evidence destruction (12 queries)
• Emergency powers (12 queries)
• Justice system manipulation (12 queries)
• Election compromise (12 queries)
• False flag indicators (12 queries)
• IC purges (12 queries)
• Military changes (12 queries)
• Surveillance expansion (12 queries)
• Media control (12 queries)
• Financial weaponization (12 queries)
• Alliance breaking (12 queries)
• Institutional erosion (12 queries)

Total: 156 rotating queries across 4 APIs

✅ Transparency & Methodology

This framework is fully transparent and reproducible:

Source code: Open in workspace (threat_actor_indicators.py, signal_analyzer_v2.py)
Query list: All 156 queries documented in THREAT_ACTOR_FRAMEWORK.md
Algorithm: v2 deduplication by outlet (not aggregator entries)
Patterns: All 10 operational indicators defined with severity levels
Cost: Fully itemized (~$7/month)
Red lines: Explicit thresholds (6+ signals or 3+ CRITICAL patterns = RED)

No hidden logic. No black boxes. Full institutional accountability monitoring.